Virus

Virus:Win32/Expiro.CL removal

Malware Removal

The Virus:Win32/Expiro.CL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Expiro.CL virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus:Win32/Expiro.CL?


File Info:

name: 4D22642F3AFD1BD996DF.mlw
path: /opt/CAPEv2/storage/binaries/44934f6c50d5fef4a36b3578d941e033101e3ab69e324cc5342ef2d3da6025a9
crc32: 2FE5623B
md5: 4d22642f3afd1bd996df81f5aee221fb
sha1: 1f6c489558d09bf34ac151c185f1e4fc34ac148c
sha256: 44934f6c50d5fef4a36b3578d941e033101e3ab69e324cc5342ef2d3da6025a9
sha512: 46b8df7c93e30a5747b98f971a3a3104dc22c2b070ee01aea554aedb2818c187224014cd30da4e3fa410d0c78a9b23e712a781766a7a21782218d8df17723c2e
ssdeep: 12288:QWnCRlntyPfPywxa4QrcT7S05NJIPpN6mtOSIIhuX:QWnCRlteywxZ3RGPpNxOSIIhuX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10FE49ED2DD87602DFA63B3747F9C422755F48D982E886144ED0CADDA21EDE017C93A8B
sha3_384: 434fb8d8c65bb74f71e11b1b77a596bcdc9abf8637626763d9b88a51b8658e708386201976746f7d9a18935c16ebf2db
ep_bytes: 605589e581ec08010000c745e40c0000
timestamp: 2012-07-09 03:53:52

Version Info:

CompanyName: Microsoft Corporation
FileDescription: .NET Runtime Optimization Service
FileVersion: 4.0.30319.17929 built by: FX45RTMREL
InternalName: mscorsvw.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: mscorsvw.exe
ProductName: Microsoft® .NET Framework
ProductVersion: 4.0.30319.17929
Comments: Flavor=Retail
PrivateBuild: DDBLD118
Translation: 0x0409 0x04b0

Virus:Win32/Expiro.CL also known as:

BkavW32.Expiro2NHc.PE
Elasticmalicious (high confidence)
DrWebWin32.Expiro.80
MicroWorld-eScanWin32.Expiro.Gen.3
FireEyeGeneric.mg.4d22642f3afd1bd9
ALYacWin32.Expiro.Gen.3
MalwarebytesMalware.AI.2545309858
VIPREVirus.Win32.Expiro.p (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 0040f4dc1 )
K7GWVirus ( 0040f4dc1 )
Cybereasonmalicious.f3afd1
BitDefenderThetaAI:FileInfector.6CBEB04B12
CyrenW32/Expiro.BU
SymantecW32.Xpiro.F
ESET-NOD32Win32/Expiro.BA
TrendMicro-HouseCallPE_EXPIRO.AR
CynetMalicious (score: 100)
KasperskyVirus.Win32.Expiro.ar
BitDefenderWin32.Expiro.Gen.3
NANO-AntivirusVirus.Win32.Expiro.clnvwd
AvastWin32:Xpirat [Inf]
TencentVirus.Win32.Expiro.tt
EmsisoftWin32.Expiro.Gen.3 (B)
ComodoTrojWare.Win32.Spy.Zbot.AAZ@1p8hml
BaiduWin32.Virus.Expiro.c
ZillyaVirus.Expiro.Win32.56
TrendMicroPE_EXPIRO.AR
McAfee-GW-EditionBehavesLike.Win32.Ramnit.jc
SophosML/PE-A + W32/Expiro-S
IkarusVirus.Win32.Expiro
MaxSecureTrojan.Malware.121218.susgen
AviraTR/Patched.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASVirus.C5
MicrosoftVirus:Win32/Expiro.CL
ZoneAlarmVirus.Win32.Expiro.ar
GDataWin32.Expiro.Gen.3
AhnLab-V3Win32/Expiro5.Gen
VBA32BScope.Trojan.Vilsel
APEXMalicious
RisingVirus.Expiro!1.A140 (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Expiro.W
AVGWin32:Xpirat [Inf]
PandaW32/Expiro.O
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Virus:Win32/Expiro.CL?

Virus:Win32/Expiro.CL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment